CVE-2024-4994: GitLab

High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1.0 before 16.11.5, all versions starting from 17.0 before 17.0.3, all versions starting from 17.1.0 before 17.1.1 which allowed for a CSRF attack on GitLab's GraphQL API leading to the execution of arbitrary GraphQL mutations.

Affected products

  • GitLab GitLab: from 16.1.0, before 16.11.5 (fixed in 16.11.5); from 17.0.0, before 17.0.3 (fixed in 17.0.3); version 17.1.0 only

Published 2025-06-20. Last modified 2026-06-17.